FreeAccount required
ISO ↔ NIST mapper
Look up how ISO/IEC 27001:2022 Annex A controls line up with NIST CSF 2.0 subcategories, in both directions, with the coverage level of each pair.
Direction
93 controls
- A.5.1Policies for information securityOrganizational
- GV.PO-01Security policy establishedEquivalent
- GV.PO-02Policy reviewed and updatedEquivalent
- A.5.2Information security roles and responsibilitiesOrganizational
- GV.RR-02Roles and responsibilities establishedEquivalent
- GV.RR-01Leadership accountable for riskPartial
- A.5.3Segregation of dutiesOrganizational
- GV.RR-02Roles and responsibilities establishedPartial
- PR.AA-05Access permissions follow least privilegePartial
- A.5.4Management responsibilitiesOrganizational
- GV.RR-01Leadership accountable for riskEquivalent
- GV.RR-03Adequate resources allocatedPartial
- A.5.5Contact with authoritiesOrganizational
- RS.CO-02Stakeholders notifiedPartial
- GV.OC-03Legal and regulatory requirements understoodRelated
- A.5.6Contact with special interest groupsOrganizational
- ID.RA-02Cyber threat intelligence receivedPartial
- RS.CO-03Information shared with those who need itRelated
- A.5.7Threat intelligenceOrganizational
- ID.RA-02Cyber threat intelligence receivedEquivalent
- DE.AE-07Threat intelligence integrated into analysisPartial
- ID.RA-03Internal and external threats identifiedRelated
- A.5.8Information security in project managementOrganizational
- ID.RA-07Changes assessed for riskPartial
- PR.PS-06Secure software development practicesRelated
- A.5.9Inventory of information and other associated assetsOrganizational
- ID.AM-01Hardware inventoryEquivalent
- ID.AM-02Software and services inventoryEquivalent
- ID.AM-07Inventory of data and metadataPartial
- A.5.10Acceptable use of information and other associated assetsOrganizational
- GV.PO-01Security policy establishedPartial
- PR.AT-01Awareness training for all personnelRelated
- A.5.11Return of assetsOrganizational
- ID.AM-08Assets managed across the life cyclePartial
- GV.RR-04Security included in human resources practicesRelated
- A.5.12Classification of informationOrganizational
- ID.AM-05Assets prioritized by criticalityEquivalent
- ID.AM-07Inventory of data and metadataPartial
- A.5.13Labelling of informationOrganizational
- ID.AM-07Inventory of data and metadataPartial
- ID.AM-05Assets prioritized by criticalityRelated
- A.5.14Information transferOrganizational
- PR.DS-02Confidentiality and integrity of data in transitEquivalent
- ID.AM-03Network communication and data flows mappedPartial
- A.5.15Access controlOrganizational
- PR.AA-05Access permissions follow least privilegeEquivalent
- PR.AA-01Identities and credentials managedPartial
- A.5.16Identity managementOrganizational
- PR.AA-01Identities and credentials managedEquivalent
- PR.AA-02Identity proofed and bound to credentialsPartial
- A.5.17Authentication informationOrganizational
- PR.AA-03Users and services authenticatedEquivalent
- PR.AA-04Identity assertions protectedPartial
- A.5.18Access rightsOrganizational
- PR.AA-05Access permissions follow least privilegeEquivalent
- PR.AA-01Identities and credentials managedPartial
- A.5.19Information security in supplier relationshipsOrganizational
- GV.SC-01Supply chain risk program establishedEquivalent
- GV.SC-03Third-party risk integrated into the programPartial
- A.5.20Addressing information security within supplier agreementsOrganizational
- GV.SC-05Security requirements in contractsEquivalent
- GV.SC-06Due diligence before engagementPartial
- A.5.21Managing information security in the ICT supply chainOrganizational
- GV.SC-09Supply chain security across the life cycleEquivalent
- GV.SC-04Suppliers prioritized by criticalityPartial
- ID.RA-09Hardware and software integrity verifiedPartial
- A.5.22Monitoring, review and change management of supplier servicesOrganizational
- GV.SC-07Supplier risk monitored over the relationshipEquivalent
- DE.CM-06Third-party activity monitoredPartial
- ID.RA-10Critical suppliers assessedRelated
- A.5.23Information security for use of cloud servicesOrganizational
- GV.SC-05Security requirements in contractsPartial
- ID.AM-04Inventory of third-party servicesPartial
- GV.SC-10Supplier relationship terminationRelated
- A.5.24Information security incident management planning and preparationOrganizational
- ID.IM-04Response and recovery plans maintainedEquivalent
- RS.MA-01Response plan executedPartial
- A.5.25Assessment and decision on information security eventsOrganizational
- DE.AE-08Incidents declared against criteriaEquivalent
- RS.MA-03Incidents categorized and prioritizedEquivalent
- RS.MA-02Incident reports triagedPartial
- A.5.26Response to information security incidentsOrganizational
- RS.MA-01Response plan executedEquivalent
- RS.MI-01Incidents containedPartial
- RS.MI-02Incidents eradicatedPartial
- A.5.27Learning from information security incidentsOrganizational
- ID.IM-03Improvements derived from operationsEquivalent
- RS.AN-03Root cause analysis performedEquivalent
- A.5.28Collection of evidenceOrganizational
- RS.AN-07Evidence collected and preservedEquivalent
- RS.AN-06Investigation actions recordedPartial
- A.5.29Information security during disruptionOrganizational
- PR.IR-03Resilience mechanisms implementedPartial
- RC.RP-01Recovery plan executedPartial
- A.5.30ICT readiness for business continuityOrganizational
- PR.IR-03Resilience mechanisms implementedEquivalent
- RC.RP-04Critical functions restored by priorityPartial
- GV.OC-04Critical service expectations understoodRelated
- A.5.31Legal, statutory, regulatory and contractual requirementsOrganizational
- GV.OC-03Legal and regulatory requirements understoodEquivalent
- A.5.32Intellectual property rightsOrganizational
- GV.OC-03Legal and regulatory requirements understoodPartial
- ID.AM-02Software and services inventoryRelated
- A.5.33Protection of recordsOrganizational
- GV.OC-03Legal and regulatory requirements understoodPartial
- PR.DS-01Confidentiality and integrity of data at restPartial
- A.5.34Privacy and protection of PIIOrganizational
- GV.OC-03Legal and regulatory requirements understoodPartial
- ID.AM-07Inventory of data and metadataPartial
- PR.DS-01Confidentiality and integrity of data at restRelated
- A.5.35Independent review of information securityOrganizational
- GV.OV-03Program performance evaluatedEquivalent
- ID.IM-01Improvements identified from evaluationsPartial
- A.5.36Compliance with policies, rules and standardsOrganizational
- GV.OV-01Strategy outcomes reviewedEquivalent
- GV.PO-02Policy reviewed and updatedPartial
- A.5.37Documented operating proceduresOrganizational
- GV.PO-01Security policy establishedPartial
- PR.PS-01Configuration managementRelated
- A.6.1ScreeningPeople
- GV.RR-04Security included in human resources practicesEquivalent
- A.6.2Terms and conditions of employmentPeople
- GV.RR-04Security included in human resources practicesPartial
- GV.PO-01Security policy establishedRelated
- A.6.3Information security awareness, education and trainingPeople
- PR.AT-01Awareness training for all personnelEquivalent
- PR.AT-02Training for specialized rolesEquivalent
- A.6.4Disciplinary processPeople
- GV.RR-04Security included in human resources practicesPartial
- A.6.5Responsibilities after termination or change of employmentPeople
- GV.RR-04Security included in human resources practicesPartial
- PR.AA-05Access permissions follow least privilegePartial
- A.6.6Confidentiality or non-disclosure agreementsPeople
- GV.RR-04Security included in human resources practicesPartial
- GV.SC-05Security requirements in contractsRelated
- A.6.7Remote workingPeople
- PR.IR-01Networks and environments protectedPartial
- PR.AA-05Access permissions follow least privilegeRelated
- A.6.8Information security event reportingPeople
- RS.MA-02Incident reports triagedEquivalent
- DE.AE-06Detection information communicatedPartial
- A.7.1Physical security perimetersPhysical
- PR.AA-06Physical access controlledEquivalent
- A.7.2Physical entryPhysical
- PR.AA-06Physical access controlledEquivalent
- A.7.3Securing offices, rooms and facilitiesPhysical
- PR.AA-06Physical access controlledPartial
- A.7.4Physical security monitoringPhysical
- DE.CM-02Physical environment monitoredEquivalent
- A.7.5Protecting against physical and environmental threatsPhysical
- PR.IR-02Assets protected from environmental threatsEquivalent
- A.7.6Working in secure areasPhysical
- PR.AA-06Physical access controlledPartial
- DE.CM-02Physical environment monitoredRelated
- A.7.7Clear desk and clear screenPhysical
- PR.DS-10Data in use protectedPartial
- PR.AT-01Awareness training for all personnelRelated
- A.7.8Equipment siting and protectionPhysical
- PR.IR-02Assets protected from environmental threatsEquivalent
- A.7.9Security of assets off-premisesPhysical
- ID.AM-08Assets managed across the life cyclePartial
- PR.IR-02Assets protected from environmental threatsPartial
- A.7.10Storage mediaPhysical
- ID.AM-08Assets managed across the life cyclePartial
- PR.DS-01Confidentiality and integrity of data at restPartial
- A.7.11Supporting utilitiesPhysical
- PR.IR-02Assets protected from environmental threatsEquivalent
- PR.IR-04Adequate capacity maintainedPartial
- A.7.12Cabling securityPhysical
- PR.IR-02Assets protected from environmental threatsPartial
- A.7.13Equipment maintenancePhysical
- PR.PS-03Hardware maintained and replacedEquivalent
- A.7.14Secure disposal or re-use of equipmentPhysical
- ID.AM-08Assets managed across the life cycleEquivalent
- PR.PS-03Hardware maintained and replacedPartial
- A.8.1User endpoint devicesTechnological
- ID.AM-01Hardware inventoryPartial
- PR.PS-01Configuration managementPartial
- A.8.2Privileged access rightsTechnological
- PR.AA-05Access permissions follow least privilegeEquivalent
- A.8.3Information access restrictionTechnological
- PR.AA-05Access permissions follow least privilegeEquivalent
- A.8.4Access to source codeTechnological
- PR.AA-05Access permissions follow least privilegePartial
- PR.PS-06Secure software development practicesRelated
- A.8.5Secure authenticationTechnological
- PR.AA-03Users and services authenticatedEquivalent
- PR.AA-02Identity proofed and bound to credentialsPartial
- A.8.6Capacity managementTechnological
- PR.IR-04Adequate capacity maintainedEquivalent
- A.8.7Protection against malwareTechnological
- DE.CM-09Hardware, software and services monitoredPartial
- PR.PS-05Unauthorized software preventedPartial
- PR.AT-01Awareness training for all personnelRelated
- A.8.8Management of technical vulnerabilitiesTechnological
- ID.RA-01Vulnerabilities identified and recordedEquivalent
- PR.PS-02Software maintained and patchedEquivalent
- ID.RA-08Vulnerability disclosure processPartial
- A.8.9Configuration managementTechnological
- PR.PS-01Configuration managementEquivalent
- A.8.10Information deletionTechnological
- ID.AM-08Assets managed across the life cyclePartial
- PR.DS-01Confidentiality and integrity of data at restPartial
- A.8.11Data maskingTechnological
- PR.DS-01Confidentiality and integrity of data at restPartial
- PR.DS-10Data in use protectedPartial
- A.8.12Data leakage preventionTechnological
- DE.CM-01Networks monitoredPartial
- DE.CM-03Personnel activity and technology usage monitoredPartial
- PR.DS-02Confidentiality and integrity of data in transitRelated
- A.8.13Information backupTechnological
- PR.DS-11Backups created, protected and testedEquivalent
- RC.RP-03Backup integrity verified before restorationPartial
- A.8.14Redundancy of information processing facilitiesTechnological
- PR.IR-03Resilience mechanisms implementedEquivalent
- PR.IR-04Adequate capacity maintainedPartial
- A.8.15LoggingTechnological
- PR.PS-04Log records generated and availableEquivalent
- A.8.16Monitoring activitiesTechnological
- DE.CM-01Networks monitoredEquivalent
- DE.CM-09Hardware, software and services monitoredEquivalent
- DE.AE-02Adverse events analyzedPartial
- DE.AE-03Information correlated from multiple sourcesPartial
- A.8.17Clock synchronizationTechnological
- PR.PS-04Log records generated and availablePartial
- DE.AE-03Information correlated from multiple sourcesRelated
- A.8.18Use of privileged utility programsTechnological
- PR.AA-05Access permissions follow least privilegePartial
- PR.PS-05Unauthorized software preventedPartial
- A.8.19Installation of software on operational systemsTechnological
- PR.PS-05Unauthorized software preventedEquivalent
- PR.PS-01Configuration managementPartial
- A.8.20Networks securityTechnological
- PR.IR-01Networks and environments protectedEquivalent
- DE.CM-01Networks monitoredPartial
- A.8.21Security of network servicesTechnological
- PR.IR-01Networks and environments protectedEquivalent
- ID.AM-04Inventory of third-party servicesPartial
- A.8.22Segregation of networksTechnological
- PR.IR-01Networks and environments protectedEquivalent
- A.8.23Web filteringTechnological
- PR.IR-01Networks and environments protectedPartial
- DE.CM-01Networks monitoredRelated
- A.8.24Use of cryptographyTechnological
- PR.DS-01Confidentiality and integrity of data at restEquivalent
- PR.DS-02Confidentiality and integrity of data in transitEquivalent
- A.8.25Secure development life cycleTechnological
- PR.PS-06Secure software development practicesEquivalent
- A.8.26Application security requirementsTechnological
- PR.PS-06Secure software development practicesPartial
- A.8.27Secure system architecture and engineering principlesTechnological
- PR.PS-06Secure software development practicesPartial
- PR.IR-01Networks and environments protectedRelated
- A.8.28Secure codingTechnological
- PR.PS-06Secure software development practicesPartial
- A.8.29Security testing in development and acceptanceTechnological
- ID.RA-01Vulnerabilities identified and recordedPartial
- PR.PS-06Secure software development practicesPartial
- A.8.30Outsourced developmentTechnological
- GV.SC-05Security requirements in contractsPartial
- PR.PS-06Secure software development practicesPartial
- GV.SC-07Supplier risk monitored over the relationshipRelated
- A.8.31Separation of development, test and production environmentsTechnological
- PR.IR-01Networks and environments protectedPartial
- PR.PS-01Configuration managementPartial
- A.8.32Change managementTechnological
- ID.RA-07Changes assessed for riskEquivalent
- PR.PS-01Configuration managementPartial
- A.8.33Test informationTechnological
- PR.DS-01Confidentiality and integrity of data at restPartial
- PR.DS-10Data in use protectedPartial
- A.8.34Protection of information systems during audit testingTechnological
- GV.OV-03Program performance evaluatedRelated
- PR.PS-01Configuration managementRelated
How to use the mapper
- 1
Choose the direction: ISO to NIST or the reverse.
- 2
Search by control identifier or keyword.
- 3
Review the matches, the coverage level, and export your selection.
Frequently asked questions
- What does coverage level mean?
- It says whether the pair covers the same objective fully, only partly, or is merely related. Cross-framework mapping is almost never one to one.
- Which version of each framework?
- ISO/IEC 27001:2022 (Annex A, 93 controls) and NIST CSF 2.0.
- Can I use this as audit evidence?
- Use it as the starting point of your crosswalk, not as evidence. Coverage has to be demonstrated with the control as implemented in your environment.
Other tools in this category
Need more?
From a one-off tool to a full program
Tools solve today's task. The Aranis platform runs the program: vendor assessment, organizational risk, privacy and continuity, with evidence and an audit trail.